166 terms · 75/46/45
Defense № 011 · class: identity / access

Zero Trust

Zero Trust is a security concept that assumes no user, device, or network segment should be automatically trusted, regardless of whether it is inside or outside the corporate network. Every access request is verified before approval.

Term

description · examples · notes

Zero Trust is a security concept that assumes no user, device, or network segment should be automatically trusted, regardless of whether it is inside or outside the corporate network. Every access request is verified before approval.

Description

Instead of the traditional approach where the network perimeter is the trust boundary, Zero Trust applies continuous verification of identity, device context, and risk level for every access request.

Implementation requires a combination of multiple technologies including MFA, micro-segmentation, user and device behavior monitoring, and context-based access policies. Zero Trust is not a product but an architectural approach.

What people often say

  • Zero Trust is a ready-made product that can be purchased and installed.
  • Zero Trust implementation is a one-time project.
  • Zero Trust means trusting nobody, even after authentication.

Covers / does not cover

Covers

  • Continuous identity and context verification on every access request
  • Least privilege principle applied to all users and services
  • Reducing the impact of a single segment compromise on the rest of the environment
  • Resource protection regardless of user or device location

Does not cover

  • Real-time threat detection and response (that is the role of EDR/XDR/SIEM)
  • Protection against application vulnerabilities
  • Data recovery after a destructive attack

Mentioned in the news

Composite

Threats

reduces 4

Techniques

neutralizes 4

Techniques it neutralizes. Select one to open its page.